-= Per source details. Do not edit below this line.=-
The newtun CLI opens a plaintext WebSocket to the hardcoded server pull.7ii.win:7999 and hands the remote peer complete control of the installer's host. On TERMOPEN messages the client calls pty.spawn(shell,...) and pipes server-supplied bytes (base64-decoded) directly into term.write(), giving the remote server an interactive PTY shell as the process user. SCRIPTLIST/POLICYSCRIPTS messages pass server-controlled string content to childprocess.exec() and return stdout/stderr/exit code back over the same socket. FILE_REQUEST messages dispatch fs.readdirSync / readFileSync / writeFileSync / unlinkSync / rmSync / renameSync / mkdirSync against server-supplied paths, with file contents shipped back base64-encoded (up to 10MB per read) — allowing the operator to exfiltrate ~/.ssh, ~/.aws, and other installer secrets and to plant or delete files anywhere the process user can write. Every 5 seconds the client also sends MONITOR frames carrying hostname, OS type/release, arch, Node version, CPU/memory/load, uptime, and /proc/net/dev RX/TX rates; the initial authenticate frame carries os.hostname(), os.type/release/arch, and process.version. An UPGRADE control message causes the client to run npm update -g newtun and relaunch, letting the remote server swap the globally installed binary for any future published version without user interaction. The transport is unauthenticated plain ws:// so any on-path party can also drive these primitives.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-017346",
"import_time": "2026-08-11T12:23:10.271014562Z",
"sha256": "10824263dc9e32215d3e220d20b6de089f684d53f71b2574f181c98daae0abf4",
"versions": [
"1.0.20"
],
"source": "amazon-inspector",
"modified_time": "2026-08-11T12:21:54Z"
},
{
"import_time": "2026-08-11T12:23:09.430120308Z",
"id": "IN-MAL-2026-017336",
"sha256": "adc90e76cf26bdb3145704cfb477f3a5215670556d03ff2959dde595a8bb0598",
"modified_time": "2026-08-11T12:20:24Z",
"source": "amazon-inspector",
"versions": [
"1.0.14"
]
},
{
"id": "IN-MAL-2026-017339",
"import_time": "2026-08-11T12:23:09.716272053Z",
"sha256": "b607f8c68e609c5cdd110266221d162b74f804210d537866f32a416ffc53d956",
"versions": [
"1.0.18"
],
"source": "amazon-inspector",
"modified_time": "2026-08-11T12:20:52Z"
},
{
"id": "IN-MAL-2026-017330",
"import_time": "2026-08-11T12:23:08.925047195Z",
"sha256": "250220a094a1f5602311f6e852e02110a606e099bc58981bbfe423daf07f60cf",
"modified_time": "2026-08-11T12:19:28Z",
"source": "amazon-inspector",
"versions": [
"1.0.25"
]
},
{
"id": "IN-MAL-2026-017337",
"import_time": "2026-08-11T12:23:09.50086685Z",
"sha256": "54a3c9472294a912f954c8660d904752aab0c5c07ba662bf65e66e99f01ba7d7",
"versions": [
"1.0.12"
],
"source": "amazon-inspector",
"modified_time": "2026-08-11T12:20:33Z"
},
{
"id": "IN-MAL-2026-017334",
"import_time": "2026-08-11T12:23:09.232257143Z",
"sha256": "bfc53f84f3fdc42574b025a376f29630faf5d5a6db55e9bc1191624ef4255f86",
"modified_time": "2026-08-11T12:20:05Z",
"source": "amazon-inspector",
"versions": [
"1.0.26"
]
},
{
"id": "IN-MAL-2026-017342",
"import_time": "2026-08-11T12:23:09.936368648Z",
"sha256": "bfe1f5dbf1f2889230487c5d57840d826ec0783ecada63469b1134cbec7d7abb",
"modified_time": "2026-08-11T12:21:18Z",
"source": "amazon-inspector",
"versions": [
"1.0.21"
]
},
{
"id": "IN-MAL-2026-017351",
"import_time": "2026-08-11T12:23:10.687063961Z",
"sha256": "d9178e3713e40cdd7a4b31dcdc6e82e2febedad348145dc7e20531a96b57e680",
"versions": [
"1.0.1"
],
"source": "amazon-inspector",
"modified_time": "2026-08-11T12:22:34Z"
},
{
"id": "IN-MAL-2026-017338",
"import_time": "2026-08-11T12:23:09.622124387Z",
"sha256": "feed96ac1b104b441cbb5bffe48e7f830882bcb379155eaea8605bc6272b9e13",
"versions": [
"1.0.13"
],
"source": "amazon-inspector",
"modified_time": "2026-08-11T12:20:44Z"
},
{
"id": "IN-MAL-2026-017345",
"import_time": "2026-08-11T12:23:10.196186524Z",
"sha256": "6fc10f37d7ac7e45368f970a5a479612a70bf9fafea0896aa0406ef9e76ee57c",
"versions": [
"1.0.8"
],
"source": "amazon-inspector",
"modified_time": "2026-08-11T12:21:45Z"
},
{
"id": "IN-MAL-2026-017344",
"import_time": "2026-08-11T12:23:10.120346571Z",
"sha256": "9a1248a5a71f269da11a6c21266b850a510fd28bd967226e6e8c1ec98a17f07f",
"versions": [
"1.0.27"
],
"source": "amazon-inspector",
"modified_time": "2026-08-11T12:21:34Z"
},
{
"id": "IN-MAL-2026-017332",
"import_time": "2026-08-11T12:23:09.072617284Z",
"sha256": "afc61cd45471791e81e7219dc417c5553357589bba81b24774514d1e0e06a3fd",
"versions": [
"1.0.16"
],
"source": "amazon-inspector",
"modified_time": "2026-08-11T12:19:46Z"
},
{
"import_time": "2026-08-11T12:23:10.045493474Z",
"id": "IN-MAL-2026-017343",
"sha256": "13b0697d9e7fd93da6a8a5fc611ea13d6ad3885b05e9707eee12dd8d5cb52553",
"modified_time": "2026-08-11T12:21:27Z",
"source": "amazon-inspector",
"versions": [
"1.0.24"
]
},
{
"import_time": "2026-08-11T12:23:09.308195115Z",
"id": "IN-MAL-2026-017335",
"sha256": "29ffdd16abfc0bfa179e4ee663c6dc3ade18914fc8eda8389eb5da44cbd8a1c6",
"modified_time": "2026-08-11T12:20:14Z",
"source": "amazon-inspector",
"versions": [
"1.0.11"
]
},
{
"id": "IN-MAL-2026-017340",
"import_time": "2026-08-11T12:23:09.789093598Z",
"sha256": "2a533a6a01df200b7fe2aa9e16275f9e8e08f8e631dd621a22ecda41bf4d29f2",
"versions": [
"1.0.17"
],
"source": "amazon-inspector",
"modified_time": "2026-08-11T12:21:01Z"
},
{
"id": "IN-MAL-2026-017348",
"import_time": "2026-08-11T12:23:10.457602384Z",
"sha256": "6864bfd4c408771ad2f8a8cb718f3bb29edcc2986fb3fcf09cb77b36ab06453d",
"versions": [
"1.0.23"
],
"source": "amazon-inspector",
"modified_time": "2026-08-11T12:22:10Z"
},
{
"id": "IN-MAL-2026-017333",
"import_time": "2026-08-11T12:23:09.147577433Z",
"sha256": "8be97e3384f529f6b3cc412e1e207bb36022d23604b83a09b0768f0e66c5ba14",
"versions": [
"1.0.19"
],
"source": "amazon-inspector",
"modified_time": "2026-08-11T12:19:53Z"
},
{
"import_time": "2026-08-11T12:23:10.611741814Z",
"id": "IN-MAL-2026-017350",
"sha256": "987e887581aae8d08d592490642a4089c72bd19b15b7f18089088758c441f42d",
"modified_time": "2026-08-11T12:22:27Z",
"source": "amazon-inspector",
"versions": [
"1.0.2"
]
},
{
"id": "IN-MAL-2026-017349",
"import_time": "2026-08-11T12:23:10.533003326Z",
"sha256": "a02551d7887d5d855587c96e21458f02aa15268d0bbf6d07df966408acb70362",
"versions": [
"1.0.0"
],
"source": "amazon-inspector",
"modified_time": "2026-08-11T12:22:17Z"
},
{
"id": "IN-MAL-2026-017347",
"import_time": "2026-08-11T12:23:10.347355041Z",
"sha256": "a0caa8712aa6037e1bfa9cf5ec3a9da52fecebdd4afcc5b26e18740fb562c2c7",
"versions": [
"1.0.3"
],
"source": "amazon-inspector",
"modified_time": "2026-08-11T12:22:02Z"
},
{
"id": "IN-MAL-2026-017331",
"import_time": "2026-08-11T12:23:08.99670604Z",
"sha256": "a0deb6bf2b7444c801814b65d3758e84e25f0a9d72038d5ddc0b95289a61a83c",
"modified_time": "2026-08-11T12:19:38Z",
"source": "amazon-inspector",
"versions": [
"1.0.15"
]
},
{
"import_time": "2026-08-11T12:23:09.861684346Z",
"id": "IN-MAL-2026-017341",
"sha256": "aa9de12f8c7eedf554ee25df6fc0a9377470180b18396c3258371bc5fc27db74",
"modified_time": "2026-08-11T12:21:11Z",
"source": "amazon-inspector",
"versions": [
"1.0.22"
]
}
]
}[
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
}
]
{
"evidence_files": [
{
"path": "dist/client.js",
"tlsh": "a2c2feda6aff4061d17379685f0f64212315e00b390bed5cbe5ce3909f625b894a2fe8",
"sha256": "c8bc1258b4424ff274357c80eb900d352f057ed7eab77be80694ca1684fbf2d3"
},
{
"path": "dist/index.js",
"tlsh": "f01232885cfb04b56927ae351b3f9812372969036109f8183b9cd3d59ff186ccd936ae",
"sha256": "6a38b179399510ce1fe6da9679bf3f637f81aa3084ef4b50df182624f2e27b76"
}
],
"package_integrity": [
{
"filename": "newtun-1.0.20.tgz",
"hashes": {
"sha1": "d7113796b916982c9ac82d533b40992a121f0ebe",
"sha512_sri": "sha512-/gtWraq5CL/ADkctbWXtM9u7ebZBeGNVDioa0lc4V3invEA9Gd7EsCJ//DFAi6QJLMlfTI/OtxzlUHbTaP88hA=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/newtun/MAL-2026-13733.json"